summary refs log tree commit diff
path: root/gnu/packages/bittorrent.scm
diff options
context:
space:
mode:
authorLeo Famulari <leo@famulari.name>2018-01-11 15:18:04 -0800
committerLeo Famulari <leo@famulari.name>2018-01-12 10:11:47 -0800
commit6b433caed2c86bf41acfa65dd507292e8a0ab2ac (patch)
treec24dfae73d33cb9f639fddb9c60e072e60124ddf /gnu/packages/bittorrent.scm
parentd95bb2957d95f0a6bb5310c97960f4484b62b74a (diff)
downloadguix-6b433caed2c86bf41acfa65dd507292e8a0ab2ac.tar.gz
gnu: transmission: Fix a DNS rebinding vulnerability that allows RCE.
* gnu/packages/patches/transmission-fix-dns-rebinding-vuln.patch: New file.
* gnu/local.mk (dist_patch_DATA): Add it.
* gnu/packages/bittorrent.scm (transmission)[source]: Use it.
Diffstat (limited to 'gnu/packages/bittorrent.scm')
-rw-r--r--gnu/packages/bittorrent.scm1
1 files changed, 1 insertions, 0 deletions
diff --git a/gnu/packages/bittorrent.scm b/gnu/packages/bittorrent.scm
index eca0646200..800a42eea5 100644
--- a/gnu/packages/bittorrent.scm
+++ b/gnu/packages/bittorrent.scm
@@ -66,6 +66,7 @@
               (uri (string-append
                     "https://transmission.cachefly.net/transmission-"
                     version ".tar.xz"))
+              (patches (search-patches "transmission-fix-dns-rebinding-vuln.patch"))
               (sha256
                (base32
                 "0pykmhi7pdmzq47glbj8i2im6iarp4wnj4l1pyvsrnba61f0939s"))))